Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.781exploits catalogados
36.771CVEs com exploração pública
24.695testados em laboratório
24.475 exploits
Exploit-DBVexDay Proof
Microsoft UPnP - Local Privilege Elevation (Metasploit)
CVE-2019-1405HIGHsob ataqueransomwarelocalwindows30 dez 2019
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows
91RISCO
abrir
Exploit-DBVexDay Proof
FreeBSD-SA-19:02.fd - Privilege Escalation
CVE-2019-5596localfreebsd30 dez 2019
In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEAS
23RISCO
abrir
Exploit-DBVexDay Proof
OpenBSD - Dynamic Loader chpass Privilege Escalation (Metasploit)
CVE-2019-19726localopenbsd30 dez 2019
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be
38RISCO
abrir
Exploit-DBVexDay Proof
Django < 3.0 < 2.2 < 1.11 - Account Hijack
CVE-2019-19844webappspython24 dez 2019
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address
35RISCO
abrir
Exploit-DB
Rumpus FTP Web File Manager 8.2.9.1 - Reflected Cross-Site Scripting
CVE-2019-19368webappsasp18 dez 2019
A Reflected Cross Site Scripting was discovered in the Login page of Rumpus FTP Web File Manager 8.2.9.1. An attacker ca
43RISCO
abrir
Exploit-DBVexDay Proof
OpenMRS - Java Deserialization RCE (Metasploit)
CVE-2018-19276CRITICALremotelinux18 dez 2019
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RISCO
abrir
Exploit-DB
Telerik UI - Remote Code Execution via Insecure Deserialization
CVE-2019-18935CRITICALsob ataqueransomwarewebappsaspx18 dez 2019
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISCO
abrir
Exploit-DBVexDay Proof
Linux 5.3 - Privilege Escalation via io_uring Offload of sendmsg() onto Kernel Thread with Kernel Creds
CVE-2019-19241locallinux16 dez 2019
In the Linux kernel before 5.4.2, the io_uring feature leads to requests that inadvertently have UID 0 and full capabili
23RISCO
abrir
Exploit-DBVexDay Proof
OpenBSD 6.x - Dynamic Loader Privilege Escalation
CVE-2019-19726localopenbsd16 dez 2019
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be
38RISCO
abrir
Exploit-DB
Roxy Fileman 1.4.5 - Directory Traversal
CVE-2019-19731webappsaspx16 dez 2019
Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary loc
28RISCO
abrir
Exploit-DB
Lenovo Power Management Driver 1.67.17.48 - 'pmdrvs.sys' Denial of Service (PoC)
CVE-2019-6192MEDIUMdoswindows12 dez 2019
A potential vulnerability has been reported in Lenovo Power Management Driver versions prior to 1.67.17.48 leading to a
33RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC - Heap-Based Memory Corruption due to Malformed TTF Font
CVE-2019-16451doswindows11 dez 2019
Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier v
35RISCO
abrir
Exploit-DB
AppXSvc 17763 - Arbitrary File Overwrite (DoS)
CVE-2019-1476doswindows11 dez 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
23RISCO
abrir
Exploit-DB
Apache Olingo OData 4.0 - XML External Entity Injection
CVE-2019-17554webappsjava11 dez 2019
The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resoluti
28RISCO
abrir
Exploit-DB
Mozilla FireFox (Windows 10 x64) - Full Chain Client Side Attack
CVE-2019-9810localwindows_x86-6407 dez 2019
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check
28RISCO
abrir
Exploit-DB
Mozilla FireFox (Windows 10 x64) - Full Chain Client Side Attack
CVE-2019-11708CRITICALsob ataquelocalwindows_x86-6407 dez 2019
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result
90RISCO
abrir
Exploit-DB
Integard Pro NoJs 2.2.0.9026 - Remote Buffer Overflow
CVE-2019-16702remotewindows06 dez 2019
Integard Pro 2.2.0.9026 allows remote attackers to execute arbitrary code via a buffer overflow involving a long NoJs pa
28RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro Deep Security Agent 11 - Arbitrary File Overwrite
CVE-2019-15627localwindows06 dez 2019
Versions 10.0, 11.0 and 12.0 of the Trend Micro Deep Security Agent are vulnerable to an arbitrary file delete attack, w
23RISCO
abrir
Exploit-DB
Verot 2.0.3 - Remote Code Execution
CVE-2019-19576webappsphp06 dez 2019
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! an
28RISCO
abrir
Exploit-DBVexDay Proof
Broadcom CA Privilged Access Manager 2.8.2 - Remote Command Execution
CVE-2018-9021webappswindows05 dez 2019
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to exec
23RISCO
abrir
Exploit-DBVexDay Proof
Broadcom CA Privilged Access Manager 2.8.2 - Remote Command Execution
CVE-2018-9022webappswindows05 dez 2019
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to exec
28RISCO
abrir
Exploit-DB
Cisco WLC 2504 8.9 - Denial of Service (PoC)
CVE-2019-15276HIGHdoshardware04 dez 2019
Cisco Wireless LAN Controller HTTP Parsing Engine Denial of Service Vulnerability
53RISCO
abrir
Exploit-DB
Intelbras Router RF1200 1.1.3 - Cross-Site Request Forgery
CVE-2019-19516webappshardware03 dez 2019
Intelbras WRN 150 1.0.18 devices allow CSRF via GO=system_password.asp to the goform/SysToolChangePwd URI to change a pa
23RISCO
abrir
Exploit-DB
Revive Adserver 4.2 - Remote Code Execution
CVE-2019-5434webappsphp03 dez 2019
An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() cal
43RISCO
abrir
Exploit-DBVexDay Proof
Internet Explorer - Use-After-Free in JScript Arguments During toJSON Callback
CVE-2019-1429HIGHsob ataquedoswindows22 nov 2019
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RISCO
abrir
Exploit-DB
GNU Mailutils 3.7 - Privilege Escalation
CVE-2019-18862locallinux21 nov 2019
maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode.
23RISCO
abrir
Exploit-DBVexDay Proof
FusionPBX - Operator Panel exec.php Command Execution (Metasploit)
CVE-2019-11409remotemultiple20 nov 2019
app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerabili
60RISCO
abrir
Exploit-DBVexDay Proof
Ubuntu 19.10 - Refcount Underflow and Type Confusion in shiftfs
CVE-2019-15791HIGHdoslinux20 nov 2019
Reference count underflow in shiftfs
41RISCO
abrir
Exploit-DBVexDay Proof
Bludit - Directory Traversal Image File Upload (Metasploit)
CVE-2019-16113remotephp20 nov 2019
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISCO
abrir
Exploit-DBVexDay Proof
Ubuntu 19.10 - ubuntu-aufs-modified mmap_region() Breaks Refcounting in overlayfs/shiftfs Error Path
CVE-2019-15794HIGHdoslinux20 nov 2019
Reference counting error in overlayfs/shiftfs error path when used in conjuction with aufs
41RISCO
abrir
anteriorpágina 55 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.